Junglewise Threat Intelligence

CVE-2026-17896: Google Chrome use after free in DevTools

CVE-2026-17896 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its DevTools component could allow a remote attacker to execute unauthorized code within the browser's security sandbox if a user visits a specially crafted website. While the sandbox limits the attacker's access to the rest of the computer, this could still lead to the compromise of browser data or be used as part of a larger attack chain.

Technical details

A use-after-free (UAF) vulnerability exists in the DevTools component of Google Chrome prior to version 151.0.7922.72. The flaw is triggered when the browser incorrectly manages memory during the processing of a specially crafted HTML page. A remote, unauthenticated attacker can exploit this to achieve arbitrary code execution (RCE) within the context of the browser's sandboxed process. This vulnerability is tracked as CWE-416. Users are advised to update to version 151.0.7922.72 or later to mitigate the risk.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats